Access Control
Access Control in Atlan covers identity and access management (SSO, SCIM, users, groups, roles), permissions (personas, purposes, connection access, visibility), and audit logs. Configure who can sign in, what they can see, and how their activity is tracked.
ALTR
Integrate ALTR with Atlan and import trusted ALTR classification results as governance tags.
API audit usage
Reference for the four audit surfaces Atlan exposes for API usage—asset audit search, authentication event streaming, workflow run history, and tenant log export—plus what's not available today.
Atlan AI security
Security and compliance information for Atlan AI, including AI architecture, data handling, encryption, model management, and compliance frameworks.
Atlan architecture
Understand the Atlan architecture: platform components, management components, and central services across AWS, Azure, and GCP deployments.
Atlan MCP security
How the Atlan MCP server handles authentication, authorization, data handling, tool controls, logging, and network security—with no shared state between tenants and no data sent to LLMs.
BigID
Integrate with BigID and enrich assets in Atlan with BigID-discovered privacy metadata.
Cloud logging and monitoring
Learn about Atlan's Cloud logging and monitoring exported in OpenTelemetry Protocol (OTLP) specification for SIEM integration and security monitoring.
Compliance standards and assessments
Learn about compliance standards and assessments.
Configure network security
Configure firewall rules and network policies to secure communication between Self-Deployed Runtime and Atlan services
Configure session timeouts
Set how long an Atlan session stays valid before it expires. Configure idle timeout, max timeout, and Remember Me settings for all users in the workspace.
Cross-region private network connectivity
Learn how Atlan supports private network connectivity to data sources in different AWS regions and across cloud providers.
Customer environment security
Customer environment security best practices for deploying and operating Self-Deployed Runtime
Cyera
Integrate with Cyera and enrich assets in Atlan with Cyera-discovered data classification metadata.
Deployment and security
Frequently asked questions about Self-Deployed Runtime deployment and security
Deployment architecture
The Atlan Secure Agent is a Kubernetes-based application that runs within a customer's environment. It acts as a gateway between the single-tenant Atlan SaaS and external systems like Snowflake, Tableau, and other data sources. This document explains the Secure Agent's deployment architecture, key components, communication flows, and security considerations.
Enable event logs in AWS
Configure S3 bucket replication to receive IAM service event logs from Atlan
Enable event logs in Azure
Configure object replication to sync IAM service event logs to your Azure Storage
Enable event logs in GCP
Configure Logs Router to sync IAM service event logs from Atlan's Log Explorer to your GCP destination
Encryption and key management
Learn about encryption and key management.
How Atlan connects to ALTR
Understand how Atlan securely connects to ALTR and imports classification metadata.
How Atlan connects to Hive
Understand how Atlan securely connects to your Hive database to extract metadata, with support for multiple authentication methods and deployment modes.
How Atlan connects to PostgreSQL
Understand how Atlan securely connects to your PostgreSQL database to extract metadata, with support for multiple authentication methods and deployment modes
Immuta
Configure Immuta access request links on Atlan assets and request data access or masking exceptions directly from asset profiles.
Import ALTR classification metadata
Configure and run the Atlan ALTR workflow to import ALTR classification results into Atlan.
Incident response plan
Learn about incident response plan.
Infrastructure security
Learn about infrastructure security.
Install on AWS EKS
This guide provides step-by-step instructions to install the Secure Agent on an Amazon Elastic Kubernetes Service (AWS EKS) cluster.
Integrate Immuta
Configure the Immuta workflow in Atlan to enrich data assets with Immuta access request links and column masking exception requests.
Manage credentials
Understand how Atlan manages authentication data throughout the application lifecycle using GUID references and secure storage.
OAuth clients
Use OAuth 2.0 Client Credentials flow for short-lived access tokens in machine-to-machine integrations
PrivateLink connectivity
Understand how AWS PrivateLink ensures all metadata traffic between Atlan and AWS SageMaker Unified Studio stays within the AWS private network.
Roles and permissions
Explanation of Snowflake's security model and role requirements for data quality operations.
Secure Agent
The Atlan Secure Agent is a lightweight, Kubernetes-based application that enables secure metadata extraction. It connects internal systems with Atlan SaaS while keeping sensitive data protected and doesn’t require inbound connectivity. Running within an organization’s controlled environment, the Secure Agent ensures compliance with security policies and automates metadata processing.
Security
Frequently asked questions about security controls and access protections for Lakehouse.
Security
Security overview and controls for Self-Deployed Runtime
Security
Frequently asked questions about security controls and permissions for the Atlan browser extension.
Security and Compliance
Security and compliance requirements for apps in the Atlan App Marketplace.
Security for embedded apps
Common security questions when embedding your app in Atlan: authentication, tokens, and CSP.
Security monitoring
Learn about security monitoring.
Set up ALTR
Prepare your ALTR environment and generate API credentials for Atlan integration.
Set up customer managed keys
Learn how to set up customer managed keys to protect the secrets and credentials stored in Atlan.
Set up Hive
Configure permissions and authentication for Hive to enable metadata extraction in Atlan.
Set up on-premises Databricks lineage extraction
The Docker-based databricks-extractor offline tool has been sunset. For on-premises or network-restricted Databricks lineage extraction, use Self-Deployed Runtime, Secure Agent, or direct connectivity via private link.
Troubleshooting Hive connectivity
Resolve common Hive connection issues including authentication failures, Kerberos errors, TLS/MTLS certificate problems, and network connectivity issues.
Troubleshooting Salesforce connectivity
Learn about troubleshooting salesforce connectivity.
Troubleshooting ServiceNow
Why is the security\_admin role required to complete the ServiceNow integration?
Verify container images
Verify the authenticity and integrity of Self-Deployed Runtime container images with Cosign
What data does Atlan store with the Microsoft Teams integration?
Learn what data Atlan stores, what it doesn't access, and how the Microsoft Teams integration handles security and privacy.
What does Atlan import from ALTR?
Learn what ALTR metadata Atlan imports and how it's mapped to Atlan assets.
What does Atlan import from Immuta?
Learn what Atlan enriches from Immuta and how it surfaces on asset profiles.